# Starting Point to Tune Logstash

**URL:** <https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301>\
**Category:** Logstash\
**Created:** [June 19, 2025, 5:01am UTC](https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301 "2025-06-19T05:01:24Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 3, 2025, 2:41pm UTC](https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301/8 "2025-07-03T14:41:38Z")

</div>

It's not easy to get details from your posts. To summarize:

- 23 pipelines + 3 under heavy loads on 16 cores&32 GB memory

- ~10ms is event processing time for heavy loads

- everything is on 1 LS host

- pipeline.workers and pipeline.batch.size are default?

```auto
pipeline.workers # LS will use max 16
pipeline.batch.size: 125
pipeline.batch.delay: 5
pipeline.ordered: auto

```

- What are your values Xms and Xmx in jvm.options?
- Are all settings the same for pipelines? What is specific for those 3 pipelines?
- Are you using memory or persistent queue?
- How many data ES nodes are using?
- Have you checked ES logs? Especially because slow insert and DLQ.
- What is avg/max the message in those h loaded pipelines?

Since you said "my configuration was simple", there is not much code in filters, you can try with:  
_Edit: make backup before any changes_

```auto
pipeline.batch.size: 250 # only in heavy loads
compression_level => 5 # or increase to reduce load
ssl_enabled => true # yes, should be by default
pool_max => 2000 # increase to reduce reopening
pool_max_per_route => 200
ssl_supported_protocols => "TLSv1.3" # use only 1.3, should be faster to establish sec channel
resurrect_delay => 2

```

- Exclude dedicated master nodes from list
- Check ES logs(all nodes), why are you getting dlq\_routed, you can do it manually or metricbeat or agent
- Use sniffing mode, check this [thread](https://discuss.elastic.co/t/how-does-logstash-route-the-data-to-a-new-primary-es-node-not-the-old-one/141030/4).
- Investigate LS statistics for all pipelines
- Check value for `tcp_keepalive_time`, only check, do not touch on OS level.
- Allocate 2-3 nodes only to heavy loaded pipelines, other pipelines should

This is not simple optimization activity since it's on live data&load, where Jedi council don't have full information or access. I truly hope other Jedi will give own opinion.

Have you used live [pipelines monitoring](https://www.elastic.co/docs/reference/logstash/logstash-monitoring-ui) in Kibana? If not already exists, should set it

```auto
PUT _cluster/settings
{
  "persistent": {
    "xpack.monitoring.collection.enabled": true
  }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301)._
